SB20251022151 - Multiple vulnerabilities in Oracle ZFS Storage Appliance Kit 



SB20251022151 - Multiple vulnerabilities in Oracle ZFS Storage Appliance Kit

Published: October 22, 2025

Security Bulletin ID SB20251022151
Severity
Medium
Patch available
YES
Number of vulnerabilities 9
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 78% Low 22%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 9 secuirty vulnerabilities.


1) Improper input validation (CVE-ID: CVE-2025-62480)

The vulnerability allows a remote privileged user to perform service disruption.

The vulnerability exists due to improper input validation within the Naming Subsystem component in Oracle ZFS Storage Appliance Kit. A remote privileged user can exploit this vulnerability to perform service disruption.


2) Improper input validation (CVE-ID: CVE-2025-62479)

The vulnerability allows a remote privileged user to perform service disruption.

The vulnerability exists due to improper input validation within the Block Storage component in Oracle ZFS Storage Appliance Kit. A remote privileged user can exploit this vulnerability to perform service disruption.


3) Improper input validation (CVE-ID: CVE-2025-62477)

The vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Remote Replication component in Oracle ZFS Storage Appliance Kit. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.


4) Improper input validation (CVE-ID: CVE-2025-62476)

The vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Remote Replication component in Oracle ZFS Storage Appliance Kit. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.


5) Improper input validation (CVE-ID: CVE-2025-62478)

The vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Object Store component in Oracle ZFS Storage Appliance Kit. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.


6) Improper input validation (CVE-ID: CVE-2025-62289)

The vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Filesystems component in Oracle ZFS Storage Appliance Kit. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.


7) Improper input validation (CVE-ID: CVE-2025-62475)

The vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Core component in Oracle ZFS Storage Appliance Kit. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.


8) Improper input validation (CVE-ID: CVE-2025-53046)

The vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper input validation within the Analytics component in Oracle ZFS Storage Appliance Kit. A remote privileged user can exploit this vulnerability to perform a denial of service (DoS) attack.


9) Improper input validation (CVE-ID: CVE-2025-62290)

The vulnerability allows a remote privileged user to execute arbitrary code.

The vulnerability exists due to improper input validation within the Block Storage component in Oracle ZFS Storage Appliance Kit. A remote privileged user can exploit this vulnerability to execute arbitrary code.


Remediation

Install update from vendor's website.